Details TACACS+ server concepts, including server parameters, configuration procedures for hosts, group, and AAA integration, and step-by-step tasks for server authorization, authentication, and accounting.
A TACACS+ server is a remote AAA endpoint that
-
exchanges authentication, authorization, and accounting (AAA) data with Cisco IOS XR over TCP
-
supports configuration of parameters such as port, timeout, shared key, and single-connection options, and
-
is subject to global server-count limits and specific behaviors related to source interfaces.
Feature history
|
Feature Name |
Release Information |
|
|---|---|---|
|
TACACS+ Server |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
Additional reference information
-
By default, the TACACS+ port is standard port 49 if no other port is specified.
-
Timeout and key parameters can be configured globally or on a per-server basis.
-
The single-connection option allows all TACACS+ requests to one server to be multiplexed over a single TCP connection.
-
Cisco IOS XR supports up to 30 global TACACS+ servers.